CVE-2018-13433: Boostnote
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
Affected products
- Boostnote Boostnote: version 0.11.7 only
Published 2018-07-08. Last modified 2026-06-17.